SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (E-mail Server)  >   Sendmail Vendors:   Sendmail Consortium
(Immunix Issues Fix) Sendmail Command Line Debugging Validation Flaw Lets Local Users Execute Arbitrary Code and Gain Root Privileges
SecurityTracker Alert ID:  1002265
SecurityTracker URL:  http://securitytracker.com/id/1002265
CVE Reference:   CVE-2001-0653   (Links to External Site)
Date:  Aug 27 2001
Impact:   Execution of arbitrary code via local system, Root access via local system
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): versions between 8.10.0 and 8.11.5 as well as all 8.12.0.Beta versions
Description:   SecurityFocus discovered an input validation vulnerability in the Sendmail '-d' debugging facility that allows a local user to execute arbitrary code with root level privileges.

The vulnerability is reportedly due to a flaw in the use of signed integers in Sendmail's tTflag() debugging function.

A remote user can call sendmail with the '-d' command line switch and can supply a large value for the 'category' part of the arguments to be used as an index for the system's internal trace vector. The user-supplied arguments can apparently cause a signed integer overflow such that the input validation function does not detect that the size of the user-supplied trace vector data exceeds the indicated (and overflowed) length value.

It is reported that the trace vector data is written before the program drops its set user id (suid) root privileges. As a result, a local user can overwrite process memory and cause arbitrary code to be executed with root privileges.

Impact:   A local user can invoke sendmail and cause arbitrary code to be executed with root level privileges, giving the user root level access on the system.
Solution:   The vendor has released a fix. See the Source Message for the vendor's advisory containing directions on how to obtain the appropriate fix.
Vendor URL:  www.sendmail.org/ (Links to External Site)
Cause:   Input validation error
Underlying OS:   Linux (Immunix)

Message History:   This archive entry is a follow-up to the message listed below.
Aug 21 2001 Sendmail Command Line Debugging Validation Flaw Lets Local Users Execute Arbitrary Code and Gain Root Privileges



 Source Message Contents

Date:  Fri, 24 Aug 2001 17:25:34 -0700
Subject:  [Immunix-announce] ImmunixOS 7.0 sendmail update


-----------------------------------------------------------------------
	Immunix OS Security Advisory

Packages updated:	sendmail
Affected products:	Immunix OS 7.0
Bugs fixed:		immunix/1615, immunix/1690
Date:			Thu Aug 23 2001
Advisory ID:		IMNX-2001-70-032-01
Author:			Seth Arnold <sarnold@wirex.com>
-----------------------------------------------------------------------

Description:
  This update fixes two problems with sendmail. The first is a fairly
  serious problem handing command line arguments that can lead to root
  privileges, discovered by Cade Cairns. The second is a race condition
  with the signal handling, discovered by Michal Zalewski, with root
  access a possibility.

  StackGuard protection from the first problem is minimal -- while it
  may prevent trivial exploits from running, StackGuard should not be
  counted an effective defense against this problem.

  We recommend users upgrade their sendmail as soon as possible. While
  Immunix OS 6.2 sendmail is not vulnerable to this problem (per Dave
  Ahmed's bugtraq post), we have not researched this issue -- Immunix OS
  6.2 is no longer officially supported.

  References: http://www.securityfocus.com/archive/1/187126
  http://www.securityfocus.com/archive/1/187127
  http://www.securityfocus.com/bid/3163 

Package names and locations:
  Precompiled binary packages for Immunix 7.0 are available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/sendmail-8.11.6-1_imnx.i386.rpm
  http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/sendmail-cf-8.11.6-1_imnx.i386.rpm
  http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/sendmail-doc-8.11.6-1_imnx.i386.rpm

  Source package for Immunix 7.0 is available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/SRPMS/sendmail-8.11.6-1_imnx.src.rpm

Immunix OS 7.0 md5sums:
  175d5a88678d02f1f50d788919e1e689  RPMS/sendmail-8.11.6-1_imnx.i386.rpm
  c999d8a7a9d4954085a38208bd7d3585  RPMS/sendmail-cf-8.11.6-1_imnx.i386.rpm
  b1ea88228ebb54e10f4e9c2ea95fb41d  RPMS/sendmail-doc-8.11.6-1_imnx.i386.rpm
  27873e65dadafb724d8384140ba9d1f2  SRPMS/sendmail-8.11.6-1_imnx.src.rpm

GPG verification:                                                               
  Our public key is available at <http://wirex.com/security/GPG_KEY>.           
  *** NOTE *** This key is different from the one used in advisories            
  IMNX-2001-70-020-01 and earlier.

Online version of all Immunix 6.2 updates and advisories:
  http://immunix.org/ImmunixOS/6.2/updates/

Online version of all Immunix 7.0-beta updates and advisories:
  http://immunix.org/ImmunixOS/7.0-beta/updates/

Online version of all Immunix 7.0 updates and advisories:
  http://immunix.org/ImmunixOS/7.0/updates/

NOTE:
  Ibiblio is graciously mirroring our updates, so if the links above are
  slow, please try:
    ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
  or one of the many mirrors available at:
    http://www.ibiblio.org/pub/Linux/MIRRORS.html

Contact information:
  To report vulnerabilities, please contact security@wirex.com. WireX 
  attempts to conform to the RFP vulnerability disclosure protocol
  <http://www.wiretrip.net/rfp/policy.html>.

_______________________________________________
Immunix-announce mailing list
Immunix-announce@wirex.com
http://mail.wirex.com/mailman/listinfo/immunix-announce

 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC